Report Abuse

1 Reply

Hi Fabio. From the domains you've listed, I'm going to guess this is a zero-day attack. Spammers will purchase a server package from a hosting company that automates domain creation, DNS, and even DKIM signing. So these emails appear to come from a legitimate mail server.

MessageSniffer is really good at blocking SnowShoe/Zero-Day spam. You can start a 30-day trial at Settings >> Activation >> Licensing.

You can also block these at the SMTP level at Security >> Advanced Settings >> SMTP Blocking. Add a new inbound email address block and enter *.top, *.xyz, etc.